PT-2026-26639 · Qnap · Qvr Pro
Fuzzinglabs
·
Publicado
2026-03-20
·
Atualizado
2026-04-15
·
CVE-2026-22898
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
QVR Pro versions prior to 2.7.4.14
Description
QVR Pro is affected by a missing authentication check for critical functions, allowing remote attackers to gain access to the system. The issue allows attackers to bypass authentication and access QVR Pro surveillance systems. The vulnerability has a CVSS score of 9.3, indicating a critical severity. It is described as a 'network-accessible goldmine for instant system compromise'. No information is available regarding the number of potentially affected devices or real-world exploitation incidents.
Recommendations
Update QVR Pro to version 2.7.4.14 or later.
Correção
RCE
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Qvr Pro